The AI Act omnibus has changed the compliance calendar for every company that builds or deploys artificial intelligence in the European Union. The amending regulation entered into force on 27 July 2026, three days after publication in the Official Journal, and it pushes the heaviest obligations of the AI Act well beyond the original August 2026 date.
The Council formally adopted the text on 29 June 2026, following a provisional agreement between Parliament and Council reached in May. Standalone high-risk systems listed in Annex III, such as tools used for recruitment, credit scoring or access to education, now face a deadline of 2 December 2027. High-risk AI embedded in regulated products under Annex I, including medical devices and toys, must comply by 2 August 2028.
Anyone reading the delay as a general pause would be making a costly mistake. The transparency duties in Article 50 still applied from 2 August 2026, so chatbots must tell users they are talking to a machine, and providers of emotion recognition, biometric categorisation and deepfake tools must meet their disclosure duties. The rules for general-purpose AI models in Articles 51 to 55 also kept their original schedule.
Watermarking shows how selective the relief is. Generative systems already on the market before 2 August 2026 get a grace period until 2 December 2026 to mark synthetic audio, image, video and text. New generative features launched after that date receive no grace period at all, which means product teams cannot treat the AI Act omnibus as a reason to ship unlabelled output.
The omnibus also adds new prohibitions. It bans AI systems that generate non-consensual intimate imagery and child sexual abuse material, and the ban applied as soon as the amending text entered into force. Lawmakers treated this addition to the AI Act omnibus as a response to the spread of so-called nudifier apps, and it gives national market surveillance authorities a clear legal basis to act against them.
Several technical changes will matter to compliance lawyers. The agreement extends certain simplification measures for small and medium-sized enterprises to small mid-cap companies, and it restores the obligation to register high-risk systems in the EU database. Processing of sensitive personal data to detect bias is allowed only where it is strictly necessary. Machinery is carved out of direct AI Act coverage and handled through the Machinery Regulation instead, while each member state must have at least one regulatory sandbox running by 2 August 2027.
The political bargain behind the AI Act omnibus was plain. Industry and several capitals argued that harmonised standards were not ready, and that enforcing high-risk rules without them would create legal uncertainty. Civil society groups and a number of MEPs replied that postponement rewards late preparation. The compromise keeps the principles intact, trims the burden for smaller firms and adds firm new bans.
The wider Digital Omnibus, covering GDPR, NIS2 and the Data Act, is still moving through the ordinary legislative procedure, so the AI Act omnibus is only the first part of the simplification agenda to become law. Companies should now map each system to its new deadline, finish watermarking work before 2 December 2026 and plan for conformity assessment in 2027 and 2028. The AI Act omnibus buys time, but it does not remove the work.





